
What is a stir shaken certificate?
Key Facts
- STIR/SHAKEN coverage remains limited at 33.9% of calls signed at termination as of April 2024 according to TransNexus analysis
- A-level attestation increased to 28.0% of signed calls in April 2024, up from 26.5% in March per TransNexus data
- STIR/SHAKEN authenticates caller identity but does not assess call intent or spam status as confirmed by Numeracle
- Illegitimate A-level attestations persist among some providers despite rising adoption rates per TransNexus warning
- FCC requires all carriers to implement STIR/SHAKEN with full compliance mandated by June 30, 2023 per 46 Labs implementation guide
- CallMyLeads uses STIR/SHAKEN attestation as one signal among many in lead verification workflows per CallMyLeads business context
- Robocall volume decreased slightly by 0.45% in April 2024 across all attestation levels per TransNexus statistics
Understanding STIR/SHAKEN: How Caller ID Authentication Works
Understanding how caller ID authentication works starts with recognizing the growing problem of spoofed calls that erode trust in phone communications. STIR/SHAKEN addresses this by using digital certificates to verify that a calling number legitimately belongs to the entity placing the call, forming a critical foundation for combating illegal robocalls and spoofing attempts.
The framework operates through a three-level attestation model where originating providers assign a trust level based on their relationship with the caller. Full Attestation (A) indicates the provider knows the customer and verifies they are authorized to use the calling number. Partial Attestation (B) applies when the customer is known but the number cannot be verified. Gateway Attestation (C) is used for calls where the customer or number is unknown, such as those entering the network from international gateways or unverified sources. These levels help terminating carriers assess trust but do not guarantee call approval, as carriers may still apply additional screening based on call analytics.
At the technical core, STIR/SHAKEN relies on public key cryptography where a SHAKEN certificate issued by an authorized Certificate Authority enables the originating provider to digitally sign calls. The STIR header includes a JSON Web Token containing the calling and called numbers along with the attestation level, encrypted with the provider's private key. Upon receipt, the terminating carrier attempts to decrypt this token using the provider's public key; successful decryption confirms the calling number has not been spoofed and the attestation level is valid, while failure indicates potential tampering or lack of authentication.
This authentication process is now mandatory under FCC rules, with full implementation required for all carriers and voice service providers by June 30, 2023, and ongoing enforcement in subsequent years. Despite this mandate, coverage remains limited—only 33.9% of calls were signed at termination in April 2024, a figure TransNexus attributes largely to widespread non-IP interconnections across the telephone network that hinder end-to-end signing. Among signed calls, A-level attestation represented 28.0% in April 2024, up from 26.5% in March, though concerns persist about illegitimate A-level attestations being issued by some providers.
For businesses like CallMyLeads, STIR/SHAKEN provides a valuable signal in lead verification by confirming caller ID authenticity, which enhances trust in inbound communications. However, it is important to recognize that authentication does not equate to spam or scam detection—verified calls can still be unwanted or fraudulent, as STIR/SHAKEN validates identity but not intent. This distinction underscores the need for layered verification approaches that combine caller ID authentication with additional screening tools to effectively assess lead quality and protect against spoofing-related risks.
Why STIR/SHAKEN Matters for Lead Verification and Spam Prevention
For businesses relying on lead response, caller ID trust is foundational to effective verification. STIR/SHAKEN provides cryptographic assurance that a calling number hasn't been spoofed, allowing services like CallMyLeads to establish baseline authenticity before assessing lead intent. This identity verification layer is especially valuable when combined with AI-driven qualification, as it reduces noise from obviously fraudulent sources while preserving focus on genuine opportunities.
A-level attestation—indicating the originating provider knows both the customer and their authorized use of the number—signals higher lead quality in practice. As of April 2024, 28.0% of signed calls carried Full Attestation (A), up from 26.5% in March, reflecting gradual but meaningful adoption of stronger identity verification. However, TransNexus warns that illegitimate A-level attestations persist among some providers, underscoring that attestation alone cannot confirm call legitimacy or intent.
STIR/SHAKEN authenticates identity but does not evaluate whether a call is wanted, spam, or fraudulent—a critical distinction for lead verification systems. Even authenticated calls can be mislabeled by third-party analytics due to call reputation algorithms, not STIR/SHAKEN failure. Therefore, businesses must pair attestation data with independent spam screening and intent analysis to avoid blocking legitimate leads or accepting risky ones. This layered approach ensures identity verification enhances, rather than replaces, comprehensive lead quality assessment.
- Prioritize A-level attested leads as stronger identity signals
- Apply additional scrutiny to C-level calls from unverified sources
- Maintain robust spam screening independent of attestation
How CallMyLeads Uses STIR/SHAKEN in Its Compliance and Lead Process
Caller ID authentication only tells you who's calling — it doesn't tell you whether the call is worth answering. That distinction sits at the heart of how CallMyLeads handles every inbound call, combining STIR/SHAKEN trust signals with its own screening so real leads get fast responses and junk never reaches your team.
Here's the important nuance: STIR/SHAKEN authenticates caller identity, not intent. A signed call with a valid certificate proves the number wasn't spoofed, but it can still be an unwanted robocall. That's why attestation levels work best as one input among many, not a verdict on their own.
CallMyLeads treats attestation data exactly that way — as a signal feeding into its lead qualification and scoring, never the final word:
- Full Attestation (A) — known caller, known number — carries the most weight in scoring, since the originating provider verified both identity and authorization.
- Partial Attestation (B) — known caller, unverified number — gets moderate trust and standard screening.
- Gateway Attestation (C) — unknown caller or number — triggers extra scrutiny before anyone spends time on the call.
One caution tempers this approach: TransNexus analysis found evidence that some providers issue "illegitimate A-level attestations," so a high attestation score alone never overrides other spam indicators. And with only 33.9% of calls signed at termination as of April 2024 — largely due to non-IP interconnections — an unsigned call may simply reflect network architecture, not a scammer. Absence of a signature is treated as neutral, not suspicious.
On the outbound side, compliance follows the FCC's Call Authentication Trust Anchor rule, effective September 18, 2025. That rule allows providers to use third parties for the technical act of signing calls, but only if the provider keeps control of attestation decisions and signs with its own certificate — never the third party's. The FCC was blunt: signing traffic through a third party without meeting these requirements violates caller ID authentication rules.
The practical payoff is simple. Screened spam and robocalls never waste team time — and on metered plans, they're never billed. Real leads, whatever their attestation level, get a response in seconds, around the clock.
Want leads answered before interest fades? CallMyLeads responds to every new lead in under 10 seconds, 24/7/365 — book a free 15-minute scoping call to see how it fits your business.
Frequently Asked Questions
What is a STIR/SHAKEN certificate and what does it actually verify?
What do the A, B, and C attestation levels mean?
If a call is STIR/SHAKEN verified, does that mean it's not spam?
Is STIR/SHAKEN required by law, and since when?
Why do so many calls still show up without STIR/SHAKEN verification?
Can I trust a call with Full Attestation (A-level)?
Why Caller ID Trust Is Just the First Step
STIR/SHAKEN provides essential caller ID authentication, helping businesses verify that a number hasn’t been spoofed—but it doesn’t tell you whether a call is worth answering. As we’ve seen, even A-level attested calls can be unwanted, and with only 33.9% of calls signed at termination in April 2024, absence of attestation often reflects network limitations rather than fraud risk. For businesses relying on lead response, the real value comes from layering this identity signal with smarter screening: prioritizing A-level attested leads as stronger trust indicators while applying AI-driven qualification to assess intent and filter out spam. That’s how CallMyLeads ensures real leads get answered in seconds, around the clock, without wasting time on junk. Want to see how fast lead response can work for your business? Book a free 15-minute scoping call to learn how it fits your workflow.